<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:33:21.674277+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-274850</id>
    <title>EUVD-2026-274850</title>
    <updated>2026-10-05T15:33:21.721348+00:00</updated>
    <content>EUVD-2026-274850</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-274850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29178</id>
    <title>fkie_cve-2026-29178</title>
    <updated>2026-10-05T15:33:21.721384+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on activitypub_federation, a framework for ActivityPub federation in Rust. Prior to version 0.19.16, the GET /api/v4/image/{filename} endpoint is vulnerable to unauthenticated SSRF through parameter injection in the file_type query parameter. An attacker can inject arbitrary query parameters into the internal request to pict-rs, including the proxy parameter which causes pict-rs to fetch arbitrary URLs. This issue has been patched in version 0.19.16.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29178"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jvxv-2jjp-jxc3</id>
    <title>GHSA-jvxv-2jjp-jxc3 — Lemmy has unauthenticated SSRF via file_type query parameter injection in image endpoint</title>
    <updated>2026-10-05T15:33:21.721463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: lemmy_routes</p>
<p>## Summary</p>
<p>The `GET /api/v4/image/{filename}` endpoint is vulnerable to unauthenticated SSRF through parameter injection in the `file_type` query parameter. An attacker can inject arbitrary query parameters into the internal request to pict-rs, including the `proxy` parameter which causes pict-rs to fetch arbitrary URLs.</p>
<p>## Affected code</p>
<p>`crates/routes/src/images/download.rs`, lines 17-40 (`get_image` function):</p>
<p>```rust
pub async fn get_image(
  filename: Path&lt;String&gt;,
  Query(params): Query&lt;ImageGetParams&gt;,
  req: HttpRequest,
  context: Data&lt;LemmyContext&gt;,
) -&gt; LemmyResult&lt;HttpResponse&gt; {
  let name = &amp;filename.into_inner();
  let pictrs_url = context.settings().pictrs()?.url;
  let processed_url = if params.file_type.is_none() &amp;&amp; params.max_size.is_none() {
    format!("{}image/original/{}", pictrs_url, name)
  } else {
    let file_type = file_type(params.file_type, name);
    let mut url = format!("{}image/process.{}?src={}", pictrs_url, file_type, name);
    // ...
  };
  do_get_image(processed_url, req, &amp;context).await
}
```</p>
<p>The `file_type` parameter (`ImageGetParams.file_type: Option&lt;String&gt;`) is directly interpolated into the URL string without any validation or encoding. Since pict-rs's `/image/process.{ext}` endpoint supports a `?proxy={url}` parameter for fetching remote images, an attacker can inject `?proxy=...` via `file_type` to make pict-rs fetch arbitrary URLs.</p>
<p>This endpoint does not require authentication (no `LocalUserView` extractor).</p>
<p>## PoC</p>
<p>```b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jvxv-2jjp-jxc3"/>
  </entry>
</feed>
